Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-45762

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's IP defragmentation tracker lookup did not verify that an existing tracker used the same IP address family as the packet being processed. Under crafted fragmented IPv4/IPv6 traffic, an IPv6 fragment could be associated with an IPv4 defragmentation tracker. This can lead to a remote packet-triggered crash and denial of service when Suricata performs the relevant defragmentation. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, if using Suricata as an IDS with AF_PACKET, enabling AF_PACKET's `defrag` option may prevent Suricata from seeing such fragmented packets.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/09/2026

CVE-2026-36392

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is stored server-side and executed in the browser of any client user who visits the store page, enabling session hijacking, account takeover, and phishing.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2025-57231

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-89094

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
22/09/2026

CVE-2026-79592

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-79591

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-45752

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when certain detection transforms are chained, the decompress transform pipeline could read from an inspection buffer after it had been reallocated and freed. The issue is reached during network traffic processing, but requires a malicious rule as Suricata will crash whatever the traffic. Version 8.0.5 contains a fix. As a workaround, avoid rules that chain `gunzip` or `zlib_deflate` with `max-size` bigger than 4096 after another transform.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/09/2026

CVE-2026-45751

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's inspection-buffer helper could leave an inspection pointer referencing freed memory after a chained transform caused the backing buffer to be reallocated. The issue is reached during a specific network traffic processing, and requires a specific but not malicious rule. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, avoid rules that chain `dotprefix` transform after another one.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/09/2026

CVE-2022-26962

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-89086

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
22/09/2026

CVE-2026-89087

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The cstruct package before 6.3.0 for OCaml mishandles indexes.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-89011

Fecha de publicación:
10/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. Attackers controlling a Git server can advertise a specially crafted ref such as '__proto__/corsProxy' to reroute all subsequent network operations through an attacker-controlled proxy, causing isomorphic-git to invoke the victim's onAuth callback and transmit credentials to the attacker when the victim calls getRemoteInfo with an attacker-supplied URL.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026